Legal

Privacy Policy

CloudCastle manages and protects computers. That means our software runs on machines you own, and it necessarily sees things about them. This page explains exactly what we collect, why, how long we keep it, and what we will never do with it.

Last updated 10 August 2026

The short version. We collect what we need to keep your computers working and secure, and nothing else. We do not sell your data, we do not use it to train models for anyone else, and we do not read your personal files. Our staff can access a managed computer remotely, and every one of those sessions is logged and visible to you.

1. Who we are

CloudCastle provides remote monitoring, management, endpoint security, backup and email security software and services. In this policy, “CloudCastle”, “we” and “us” mean CloudCastle and its operating entity; “you” means the individual or organisation that holds a CloudCastle account or whose devices we manage.

For questions about this policy, or to exercise any right described in section 9, contact privacy@cloudcastle.ai.

2. Two different roles we play

This distinction matters, because it determines who you should ask about your data.

  • When you buy directly from CloudCastle (Home and Business plans), we are the controller of your data. This policy governs it, and you deal with us.
  • When your IT provider buys CloudCastle and manages you, that provider is the controller and we are their processor. We handle your data on their instructions and under our contract with them. Your relationship — including requests to see or delete data — runs through them, and we will direct you to them.

3. What we collect

Account and billing information

Name, email address, organisation name, telephone number where you supply it, and the records of your subscription. We never see or store your full card number. Card payments are processed by Stripe, which handles the card data directly; we receive only a token, the card brand, its last four digits and its expiry so that we can show you which card is on file.

Endpoint and telemetry data

From each computer running our agent, we collect operational data needed to manage it:

  • Hardware and operating-system inventory: model, serial number, machine UUID, CPU, memory, disks, OS version and patch level.
  • Network identifiers used to group a machine to the right customer site: local IP, the network gateway's hardware address, and the public IP address the machine connects from.
  • Health metrics: CPU, memory and disk utilisation, uptime, service and process state, and event-log entries relevant to faults.
  • Installed software inventory and update status, so we can patch what is out of date.
  • The username of the person signed in to the machine, used to route support and to attribute a device to the right person.
  • Security telemetry: detections, quarantine actions, and the file paths and hashes involved in them.

Remote support sessions

When a technician connects to a machine, we record who connected, when, for how long, and what actions were taken. Screen content is transmitted to conduct the session and is not recorded unless you are told and asked first.

Backup content

If you use CloudCastle Backup, we store the files and system images you have configured for backup. That content is yours. We do not open, index or analyse it, and we access it only to run the backup, to restore at your request, or where required to fix a failing job.

Email security

If you connect a mailbox, we process message metadata (sender, recipient, subject, headers, authentication results), links and attachments in order to detect phishing, impersonation and malware. Message bodies are analysed for that purpose and are not retained beyond what is needed to show you a verdict and let you release a quarantined message.

Website data

Our public site uses only what is necessary to serve pages and to keep your sign-in working. We do not run third-party advertising trackers.

4. What we do not collect

  • We do not read the contents of your documents, photographs or personal files.
  • We do not log keystrokes.
  • We do not turn on cameras or microphones.
  • We do not record browsing history for marketing.
  • We do not sell, rent or trade personal information to anyone, for any purpose.
  • We do not use your data to train machine-learning models for other customers or third parties.

5. Why we process it

To deliver the service you are paying for: monitoring, maintenance, patching, threat detection and response, backup, email protection and support. To bill you accurately. To detect and prevent fraud and abuse. To meet legal obligations. Where the law requires a lawful basis, ours is performance of our contract with you, our legitimate interest in securing and operating the service, and your consent where we ask for it.

6. Automated decisions and AI

CloudCastle uses automation, including AI, to triage alerts and to carry out a defined, pre-approved list of low-risk repairs. Higher-risk actions require a human technician. Every automated action is recorded and visible to you, and you can turn automatic remediation off. We do not make decisions with legal or similarly significant effects about individuals by automated means.

7. Who we share it with

We share personal data only with service providers who help us run CloudCastle, and only as much as each one needs:

  • Stripe — payment processing. Stripe's handling of your card data is governed by Stripe's privacy policy.
  • Infrastructure and email delivery providers — hosting our systems and sending transactional email.
  • Your IT provider, where one manages you (see section 2).

We disclose data to law enforcement only when compelled by valid legal process, and we will tell you unless we are legally prohibited from doing so. If CloudCastle is ever acquired, your data may transfer as part of that transaction, and this policy continues to apply until you are given notice of any change.

8. Where it is stored, and for how long

Data is stored on servers in the United States. We keep it for as long as your account is active, and afterwards:

  • Telemetry and health metrics: up to 13 months.
  • Security detections and audit logs: up to 24 months, because incident investigation frequently reaches back that far.
  • Backup content: for the retention period you configure, and deleted within 30 days of you cancelling or removing the backup.
  • Billing records: for as long as tax and accounting law requires, typically seven years.
  • Everything else: deleted within 90 days of account closure.

When you remove an endpoint from CloudCastle, our software uninstalls itself from that machine. If you choose the option to remove data as well, local CloudCastle state, logs and credentials are deleted from the machine too.

9. Your rights

You may ask us to show you the personal data we hold about you, correct it, delete it, export it in a portable format, or restrict how we use it. Write to privacy@cloudcastle.ai and we will respond within 30 days. We will not charge you for it and we will not treat you differently for asking.

If your data reaches us through an IT provider who manages you, send your request to that provider; we will assist them in fulfilling it.

Residents of California, Colorado, Connecticut, Virginia and other states with comparable privacy statutes hold these rights under those laws, including the right not to have personal information sold or shared — which we do not do. Individuals in the UK and EEA hold equivalent rights under the UK GDPR and GDPR, including the right to complain to a supervisory authority.

10. Security

Data is encrypted in transit with TLS and at rest. Access to production systems is limited to staff who need it, protected by multi-factor authentication, and logged. Remote-access credentials and integration secrets are encrypted with keys held separately from the database. We test our own product against the same standards we hold our customers to.

If a breach affects your data, we will notify you without undue delay and within 72 hours of becoming aware of it, together with what happened and what we are doing about it.

11. Children

CloudCastle is not directed at children under 13, and we do not knowingly collect their personal information. A household plan may protect a family computer that a child uses; that does not create an account for the child. If you believe we hold a child's data, contact us and we will delete it.

12. Changes

We will post any change here and update the date at the top. If a change materially affects how we use your data, we will email account holders at least 30 days before it takes effect.

13. Contact

Privacy: privacy@cloudcastle.ai
Support: support@cloudcastle.ai
Security reports: security@cloudcastle.ai
Postal address and registered entity details are available on request and on your invoice.